Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 71524 invoked from network); 1 Aug 2007 08:36:50 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 1 Aug 2007 08:36:50 -0000 Received: (qmail 45144 invoked by uid 500); 1 Aug 2007 08:36:07 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 44718 invoked by uid 500); 1 Aug 2007 08:36:06 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 41962 invoked by uid 99); 1 Aug 2007 08:35:55 -0000 Received: from Unknown (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 01 Aug 2007 01:35:55 -0700 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: local policy) Received: from [195.227.30.246] (HELO datura.kippdata.de) (195.227.30.246) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 01 Aug 2007 08:35:43 +0000 Received: from [195.227.30.148] (larix [195.227.30.148]) by datura.kippdata.de (8.13.5/8.13.5) with ESMTP id l718ZLBJ002004 for ; Wed, 1 Aug 2007 10:35:21 +0200 (CEST) Message-ID: <46B045C9.4030700@kippdata.de> Date: Wed, 01 Aug 2007 10:35:21 +0200 From: Rainer Jung User-Agent: Thunderbird 1.5.0.8 (X11/20061110) MIME-Version: 1.0 To: Tomcat Users List Subject: Re: Confusion about tomcat security bulletin References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on apache.org 5.0.HEAD is the most actual, non-released version of the 5.0 code branch. So this means, the problem will be fixed in any new 5.0 release. Currently there are no plans do do a new 5.0 release. So if security is a real concern for you, you should upgrade to at least 5.5 (which shouldn't be a big deal) or to 6.0. If you can't upgrade and you must fix the issue, you will need to build from the source (which is a little painful for TC 5.0). Regards, Rainer CHENG Jianhua wrote: > Dear All, > > Our company have an application use tomcat 5.0.27 and can't upgrade the > version. > I'm very concern about the security issue relate to this version. > > Now I have some confusion about tomcat security bulletin > http://tomcat.apache.org/security-5.html > . > For example: > ------------------------------------------------------------------------ > ------------------------------------------------ > Fixed in Apache Tomcat 5.5.23, 5.0.HEAD > > important: Information disclosure CVE-2005-2090 > > > Requests with multiple content-length headers should be rejected > as invalid. When multiple components (firewalls, caches, proxies and > Tomcat) process a sequence of requests where one or more requests > contain multiple content-length headers and several components do not > reject the request and make different decisions as to which > content-length leader to use an attacker can poision a web-cache, > perform an XSS attack and obtain senstive information from requests > other then their own. Tomcat now returns 400 for requests with multiple > content-length headers. > > Affects: 5.0.0-5.0.30, 5.5.0-5.5.22 > > ------------------------------------------------------------------------ > ------------------------------------------------------------------------ > -------------- > This issue does affect 5.0.27, but "Fixed in Apache Tomcat 5.5.23, > 5.0.HEAD ". Does "5.0.HEAD" include 5.0.27 itself? > If so does it mean when I get new release 5.0.27 from tomcat website > then the issue will be fixed? And if new issue has been report such as > "moderate: Cross-site scripting CVE-2007-1355 > " , it > also affects 5.0.27 and Fixed in 5.0.HEAD, does it mean I must get > 5.0.27 from tomcat website agagin to fixed this issue? > > > Look forward your answer and Thans a lot! > > Best regards, > Cheng Jianhua --------------------------------------------------------------------- To start a new topic, e-mail: users@tomcat.apache.org To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org